Skip to content

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085

Merged
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout
Jul 15, 2026
Merged

fix: retry vault read on resume-window IPC failure to prevent false sign-out#1085
coodos merged 3 commits into
mainfrom
fix/eid-wallet-resume-signout

Conversation

@Bekiboo

@Bekiboo Bekiboo commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Description of change

Fix an intermittent, unexpected sign-out in the eID Wallet: on iOS the ipc://localhost custom protocol is briefly torn down when the app resumes from background, so plugin:store|get throws — the vault getter swallowed that into undefined (looks like "logged out") and route guards redirected the user to /login. The getter now retries the read across the resume window instead of reporting a false logout.

No env/config/infra changes.

Issue Number

Closes #1084

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

  • Root cause confirmed on a physical iPhone: backgrounding then resuming the app reproduces the exact console signature — IPC custom protocol failed, Tauri will now use the postMessage interface instead – TypeError: Load failed and Fetch API cannot load ipc://localhost/plugin%3Astore%7Cget due to access control checks — with the store get throwing inside the vault getter.
  • Fix logic verified in isolation: a standalone harness mirroring #readVaultResilient asserts the three invariants — genuine logout → undefined immediately (no retry penalty); one transient resume-window throw → recovers the vault (stays logged in); persistent failure → undefined, never throws or hangs.
  • Lint: biome check passes on the changed file.
  • Known limitation: the anti-sign-out effect is not observable under tauri ios dev — dev-mode resume reloads the WebView (Vite reconnect), which independently masks the sign-out and preempts the retry loop. Real-runtime confirmation requires a release build (no Vite reload).

Design decisions

  • Fixed at the single read point (get vault()), not per-guard: one change covers the app guard, the deep-link handler and scan-qr, and leaves all ~15 callers untouched.
  • Retry on throw only, not on empty: a genuine logout is a resolved-undefined (no throw) and returns immediately, so real logouts stay instant; the ~2s retry budget (10 × 200ms) is spent only during an actual IPC-dead window.
  • Getter contract preserved: still returns Record | undefined and never throws, so no caller changes were needed.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • Bug Fixes
    • Improved vault loading reliability during app resume when storage access is temporarily unavailable.
    • Added resilient, retry-based handling for transient storage read failures, distinguishing “no vault” from actual errors.
    • Coalesced simultaneous vault requests so multiple callers share a single in-flight read, with graceful fallback when reads ultimately fail.

@Bekiboo Bekiboo self-assigned this Jul 13, 2026
@coderabbitai

coderabbitai Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1ce4c71e-2bcf-4548-99a1-023493c0befc

📥 Commits

Reviewing files that changed from the base of the PR and between d9c723e and 1e1c330.

📒 Files selected for processing (5)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/test/env-static-public.ts
  • infrastructure/eid-wallet/vitest.config.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

📝 Walkthrough

Walkthrough

VaultController now reads the persisted vault through bounded retry logic and coalesces concurrent reads. Vitest configuration and tests cover empty reads, transient failures, recovery, and subsequent fresh reads.

Changes

Vault read resilience

Layer / File(s) Summary
Retry vault store reads
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
The vault getter shares in-flight reads and delegates to #readVaultResilient(), which retries thrown store errors, distinguishes empty successful reads, and returns undefined after exhausted failures.
Validate vault read behavior
infrastructure/eid-wallet/src/lib/global/controllers/evault.spec.ts, infrastructure/eid-wallet/vitest.config.ts, infrastructure/eid-wallet/src/test/env-static-public.ts, infrastructure/eid-wallet/package.json
Adds Vitest setup and tests for no-retry empty reads, bounded retries, recovery, concurrent-read coalescing, and later re-fetches.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers: coodos, sosweetham

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: retrying vault reads to avoid false sign-outs.
Description check ✅ Passed The description matches the template well, covering the change, issue number, type, testing, and checklist.
Linked Issues check ✅ Passed The PR directly addresses #1084 by preventing unintended sign-outs when vault reads fail transiently.
Out of Scope Changes check ✅ Passed The added test script, Vitest config, and test stubs support the fix and do not appear unrelated to the issue.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-resume-signout

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Bekiboo
Bekiboo marked this pull request as ready for review July 13, 2026 13:59
@Bekiboo
Bekiboo requested a review from coodos as a code owner July 13, 2026 13:59

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts (2)

607-632: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

No test coverage for the new retry logic.

This is the core fix for a production false-sign-out bug, but there's no accompanying unit test verifying that: a resolved undefined returns immediately without retrying, a thrown error retries up to maxAttempts, and exhausted retries resolve to undefined without throwing. Worth covering with fake timers given how easy it would be to silently regress this behavior.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
607 - 632, The new `#readVaultResilient` retry behavior lacks unit coverage. Add
tests using fake timers to verify a resolved undefined returns immediately
without retrying, thrown store errors retry up to maxAttempts, and exhausted
retries return undefined without throwing; exercise the existing `#store.get`
behavior through the VaultController test setup.

583-632: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Concurrent vault reads during the resume window each run their own independent 10x retry cycle.

The docstring itself notes that multiple call sites (deep-link handler, scan-qr, app guard) read vault around app resume — exactly when the IPC failures this fix targets occur. Since #readVaultResilient() is invoked fresh on every get vault() access with no shared/cached in-flight promise, concurrent callers during that window each independently retry up to 10 times (~1.8s worst case), multiplying IPC calls and log noise instead of sharing one outcome.

Caching the in-flight promise (cleared once it settles) lets concurrent callers share a single retry cycle while still hitting the store fresh on the next independent access.

♻️ Proposed dedup for concurrent reads
+    `#pendingVaultRead`: Promise<Record<string, string> | undefined> | null =
+        null;
+
     get vault() {
-        return this.#readVaultResilient();
+        if (!this.#pendingVaultRead) {
+            this.#pendingVaultRead = this.#readVaultResilient().finally(
+                () => {
+                    this.#pendingVaultRead = null;
+                },
+            );
+        }
+        return this.#pendingVaultRead;
     }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts` around lines
583 - 632, Deduplicate concurrent vault reads by caching the in-flight promise
used by the vault getter and returning it to all callers while it is pending.
Clear the cached promise after it settles so later independent accesses perform
a fresh store read, while preserving the existing retry behavior and
Record-or-undefined result of `#readVaultResilient`().
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 607-632: The new `#readVaultResilient` retry behavior lacks unit
coverage. Add tests using fake timers to verify a resolved undefined returns
immediately without retrying, thrown store errors retry up to maxAttempts, and
exhausted retries return undefined without throwing; exercise the existing
`#store.get` behavior through the VaultController test setup.
- Around line 583-632: Deduplicate concurrent vault reads by caching the
in-flight promise used by the vault getter and returning it to all callers while
it is pending. Clear the cached promise after it settles so later independent
accesses perform a fresh store read, while preserving the existing retry
behavior and Record-or-undefined result of `#readVaultResilient`().

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6e6f7a2d-7e13-492b-bf0c-e6c443d58403

📥 Commits

Reviewing files that changed from the base of the PR and between 9faa3af and d9c723e.

📒 Files selected for processing (1)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts

@Bekiboo Bekiboo changed the title retry vault read on resume-window IPC failure to prevent false sign-out fix: retry vault read on resume-window IPC failure to prevent false sign-out Jul 13, 2026
@coodos
coodos merged commit 1337847 into main Jul 15, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User intermittently signed out of session without explicit logout — eID Wallet App

2 participants